Junglewise Threat Intelligence

CVE-2026-8043: Ivanti Xtraction external control of file name or path

CVE-2026-8043 · Severity: critical · CVSS 9.6 · Published 2026-05-12

Technologies: Ivanti Xtraction. Vendors: Ivanti.

Executive brief

Ivanti Xtraction is a self-service dashboard and reporting solution. A vulnerability in this software allows a logged-in user to manipulate file names to read sensitive system files or plant malicious web pages on the server. This could lead to the exposure of confidential data or be used to launch further attacks against other users of the system.

Technical details

A CWE-73 (External Control of File Name or Path) vulnerability exists in Ivanti Xtraction versions prior to 2026.2. A remote authenticated attacker with low privileges can provide specially crafted input to manipulate file paths. This allows the attacker to perform unauthorized file reads of sensitive system information and write arbitrary HTML files into web-accessible directories. Such capabilities can be leveraged for information disclosure or to facilitate client-side attacks like Cross-Site Scripting (XSS). The vulnerability is addressed in version 2026.2.

Affected products

  • Ivanti Xtraction before 2026.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-12: patched: Fixed in version 2026.2

References

Related threats